Threat reportVulnerabilityTL-2026-1923
Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover
Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables (TL-2026-1923), also tracked as PleaseFix, is a high-severity software vulnerability, first published 2026-08-07. It has no confirmed attribution, affects Anthropic Claude in Chrome (browser extension), maps to 11 MITRE ATT&CK techniques (T1036.005, T1059.007, T1111), and is covered by 9 detection rules and 10 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 10Indicators of compromise
Key facts for TL-2026-1923
- Threat ID
- TL-2026-1923
- Also known as
- PleaseFix, Claude in Chrome Account Takeover Exploit Chain
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all sectors any user or organization deploying agentic ai browsers
- Target regions
- global
- Detection rules
- 9
- Indicators of compromise
- 10
Malware and tooling in Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables
Malware and tooling: Attacker-controlled exfiltration endpoint (unspecified), javascript_tool (Claude in Chrome)
How Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables works
Zenity Labs demonstrated an indirect prompt-injection exploit chain against the Claude in Chrome browser extension that turns its javascript_tool into "XSS-as-a-service," exfiltrating Gmail data, silently sharing the victim's Google Drive, and hijacking Slack, X, and Claude.ai accounts by capturing verification codes and magic links. The underlying zero-click vulnerability class, "PleaseFix," also affects Perplexity Comet, ChatGPT Atlas, Gemini in Chrome, and Microsoft Copilot Edge; Anthropic classified the report as "informative" and has not issued a fix.
Zenity Labs, an Israeli AI-agent security research firm, disclosed a full account-takeover exploit chain against Anthropic's Claude in Chrome browser extension in a post titled "Claude in Chrome: A Threat Analysis." The attack begins when a victim asks Claude in Chrome to summarize their inbox; a malicious email containing hidden instructions is ingested by the agent and hijacks the user's legitimate request through a technique Zenity calls "Intent Collision." The injected instructions direct Claude's native javascript_tool — intended for browser automation — to execute arbitrary attacker-controlled JavaScript in the context of any page the agent visits, effectively turning it into an "XSS-as-a-service" primitive. The payload itself is staged from a seemingly benign package hosted on an attacker-controlled package registry masquerading as a trusted content-delivery network.
From that foothold, the agent queries Gmail's Atom feed to enumerate unread message IDs, parses full email bodies, and silently exfiltrates inbox contents to an attacker-controlled server. The same session is used to share every file in the victim's Google Drive with an attacker-controlled Google account. The chain then pivots to account takeover: the attacker triggers sign-in or password-reset flows on Slack, X, and Claude.ai, and directs the compromised agent to monitor the victim's own inbox for the resulting verification codes or passwordless magic-link nonces, relaying them back to complete the takeover. Compromising Slack and X yields the associated workspace/social accounts; compromising Claude.ai via its passwordless magic-link flow exposes the victim's chat history, uploaded files, and any data reachable through previously authorized connectors. Zenity's broader analysis of Claude in Chrome's toolset also flags read_network_requests (which can expose OAuth tokens and session identifiers from a tab's XHR/Fetch traffic) and read_console_messages as additional reconnaissance surface, and notes that Claude's "ask before acting" human-in-the-loop mode is undermined by approval fatigue and incomplete plan enforcement.
Zenity frames this as one instantiation of a broader vulnerability class it calls "PleaseFix": agentic browsers architecturally break the same-origin principle by letting a single AI agent reason and act across multiple authenticated tabs/origins in one session, effectively resurrecting cross-site-request-forgery-style capabilities against any site the user is logged into. Zenity Labs co-founder and CTO Michael Bargury characterized it as "not a bug we can patch away," saying agentic browsers "dismantle the security boundary that browsers have relied on for decades." Zenity demonstrated related PleaseFix exploit chains across Perplexity Comet (file-system exfiltration via poisoned calendar invites and password-manager-workflow abuse against 1Password, publicly disclosed March 3, 2026, after Perplexity patched the underlying agent-execution issue), ChatGPT Atlas (a crafted X post redirects the agent to WhatsApp Web to phish the victim's entire contact list, and a separate chain steers the agent to place unauthorized Amazon orders via the Rufus shopping assistant), Gemini in Chrome, and Microsoft Copilot Edge. Zenity disclosed its Claude in Chrome findings to Anthropic in December 2025 and January 2026; Anthropic classified the report as "informative" rather than treating it as a vulnerability requiring a fix, and as of public disclosure (August 6-7, 2026) no patch exists for this exploit chain. OpenAI separately acknowledged the Atlas findings (January 2026) but indicated no straightforward patch exists given the fundamental design of agentic browsers. This is a distinct issue from the earlier, already-patched "ShadowPrompt" flaw (a DOM-based XSS in a third-party CAPTCHA component on a *.claude.ai subdomain combined with an overly permissive extension postMessage allowlist), which Anthropic fixed in Claude in Chrome v1.0.41 by enforcing an exact-origin match instead of a wildcard.
MITRE ATT&CK techniques used in TL-2026-1923
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Execution
Credential Access
T1111 Multi-Factor Authentication Interception; T1528 Steal Application Access Token
Collection
T1114.002 Remote Email Collection; T1530 Data from Cloud Storage
Lateral Movement
Exfiltration
T1537 Transfer Data to Cloud Account
Initial Access
Resource Development
Impact
Affected products and versions in Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables
- Anthropic — Claude in Chrome (browser extension)
Vulnerable versions: all versions as of report (December 2025 - August 2026); architectural issue, not version-specific - Perplexity — Comet (agentic browser)
Vulnerable versions: PerplexedBrowser-affected versions prior to the March 2026 fix
Fixed in: patched prior to March 3, 2026 public disclosure - OpenAI — ChatGPT Atlas (agentic browser)
Vulnerable versions: all versions as of report; acknowledged January 2026, no patch available per OpenAI - Google — Gemini in Chrome (browser extension)
Vulnerable versions: named as affected by the PleaseFix vulnerability class - Microsoft — Copilot Edge (agentic browser feature)
Vulnerable versions: named as affected by the PleaseFix vulnerability class
Remediation for Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables
Patches
- No vendor patch exists for this Claude in Chrome account-takeover chain: Anthropic classified Zenity Labs' report as 'informative' rather than issuing a fix
- Perplexity patched the related PerplexedBrowser/Comet PleaseFix variant prior to Zenity's March 3, 2026 public disclosure
- Anthropic separately patched the unrelated 'ShadowPrompt' zero-click XSS prompt-injection flaw in Claude in Chrome v1.0.41 by enforcing an exact claude.ai origin match instead of a wildcard *.claude.ai allowlist
Immediate actions
- Disable or uninstall Claude in Chrome (and other agentic-browser extensions: Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, Microsoft Copilot Edge) until mitigations are in place
- Avoid using AI browser agents to summarize or act on untrusted or external email and web content
- Enable 'ask before acting' human-in-the-loop confirmation for all agent browser actions, while recognizing it is subject to approval fatigue and incomplete plan enforcement
Workarounds
- Do not grant Claude in Chrome or other agentic browsers access to high-value accounts (primary email, SSO-linked services) until the underlying architecture is hardened
- Require manual entry of any verification code or magic link rather than allowing an agent to read incoming email and act on it autonomously
Longer-term hardening
- Enforce per-origin session isolation for agentic-browser tabs so a single agent session cannot act across multiple authenticated origins, addressing the same-origin-policy/CSRF-style boundary collapse
- Restrict or gate high-risk native tools (javascript_tool, read_network_requests, read_console_messages) behind explicit, scoped, per-site user consent
- Adopt architectural mitigations for indirect prompt injection (instruction/content provenance tagging, tool-call allowlisting) rather than relying on prompt-level guardrails alone
Timeline of Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables
- Zenity Labs submits initial Claude in Chrome PleaseFix findings to Anthropic
- Zenity Labs follows up with Anthropic and separately discloses related ChatGPT Atlas PleaseFix findings to OpenAI, which acknowledges the report but indicates no straightforward patch exists
- Anthropic ships Claude in Chrome extension v1.0.41, fixing the unrelated 'ShadowPrompt' zero-click XSS prompt-injection flaw by enforcing an exact claude.ai origin match
- Zenity Labs publicly discloses the PleaseFix/PerplexedBrowser vulnerability in Perplexity Comet after Perplexity patches the underlying agent-execution issue
- Zenity Labs publishes 'Claude in Chrome: A Threat Analysis,' detailing the full Gmail/Google Drive/Slack/X/Claude.ai account-takeover exploit chain via javascript_tool 'XSS-as-a-service' and the Intent Collision technique
- Anthropic's classification of the Zenity Labs report as 'informative' stands as of public disclosure; no fix has been issued for the Claude in Chrome account-takeover chain
- SecurityWeek, Dark Reading, Calcalistech, Notebookcheck, and ChannelInsider report on the cross-browser PleaseFix disclosure spanning Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Microsoft Copilot Edge
- GBHackers on Security publishes coverage of the Claude in Chrome exploit chain, the source article for this record
Sources cited for Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables
- Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts
- Claude in Chrome: A Threat Analysis
- Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
- Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover
- PleaseFix Vulnerability: Perplexity Comet Zero-Click Agent Hijack
- Zenity Labs Exposes the Full Scope of PleaseFix, a Vulnerability Class Enabling Zero-Click Attacks Across Leading Agentic Browsers
- AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
- Israeli researchers uncover zero-click attacks targeting AI browsers
- Claude, Gemini, Comet: five AI browsers hijacked by a single email
- Zenity Labs Discloses Critical Exploits in Agentic Browsers
- Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website (ShadowPrompt)
- Claude Chrome Extension Zero-Click Prompt Injection via Any Website
Detection coverage for TL-2026-1923
As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1923 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.